CVEs from 2017

11,845 normalized CVEs published or assigned in this year.

Total
11,845
critical
critical 1,647
high
high 5,043
medium
medium 4,165
low
low 159
% Critical
13.9%
% with KEV
0.7%
% with exploit
0.8%

Top vendors

Top products

  • imagemagick 1,426
  • joomla\! 932
  • kanboard 848
  • ntp 762
  • tomcat 676
  • mahara 572
  • postgresql 492
  • asterisk 435
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2017-5070 critical 10.0 4y ago multiple issues in chromium arch
CVE-2017-5030 critical 10.0 4y ago multiple issues in chromium arch
CVE-2017-9841 critical 10.0 4y ago PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., exte… archdebianphp
CVE-2017-9417 critical 9.8 9.8 9y ago Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. debian
CVE-2017-7494 high 9.5 3y ago Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. archsusedebian
CVE-2017-8291 high 9.5 4y ago Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. archsusedebian
CVE-2017-16651 high 9.5 5y ago Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the … archdebian
CVE-2017-0781 high 8.8 8.8 9y ago A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.
CVE-2017-13156 high 7.8 7.8 9y ago An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847. debian
CVE-2017-0412 high 7.8 7.8 9y ago An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as H…
CVE-2017-0411 high 7.8 7.8 9y ago An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as H…
CVE-2017-1000253 unknown 1.5 2y ago Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability w… susedebian
CVE-2017-9791 unknown 1.5 4y ago Code execution in Apache Struts 1 plugin java
CVE-2017-1000353 unknown 1.5 4y ago Deserialization of Untrusted Data in Jenkins java
CVE-2017-1000486 unknown 1.5 5y ago Inadequate Encryption Strength java
CVE-2017-5638 unknown 1.5 8y ago Apache Struts vulnerable to remote arbitrary command execution due to improper input validation java
CVE-2017-9805 unknown 1.5 8y ago REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering java
CVE-2017-13216 unknown 1.0 In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged… debian